DisclosureLens
AccidentalHealthcareHealthcareMisconfigurationSupply Chain (3P Vendor)Customer Data InvolvedPHIHealth (basic)Identity (basic)LowContained

Cottage Health System

bd_99ad03604447cdd0 · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 2, 2013

Filed

Dec 11, 2013

To disclose

9 days

Affected

Not disclosed

Linked

2 filings

Confidence

66%
Full breach record for Cottage Health System2 incidents on file

Cottage Health System disclosed that a third-party vendor removed electronic security protections from a server, exposing patient health information including diagnoses and lab results. The incident was discovered on December 2, 2013, when the organization received a voicemail indicating the data was accessible via Google. The server was immediately taken offline, and the organization offered identity theft protection services to affected individuals.

California clockDiscovered Dec 2, 2013Notified Dec 5, 20133d CA 60-day OK9 days discovery → filing

Incident timeline

discovery → filing · 9 days

Dec 2, 2013

Discovered

Dec 11, 2013

Filed

vs. sector median

11 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
California State AGDec 11 · first · this page

Pattern: first filing Dec 11 (CA), last Feb 7 — a 1884-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.